Daily OT Security News: September 08, 2026

Today’s verified developments cover critical vulnerabilities, exploit chains, AI-assisted PLC research, federal incident-reporting fragmentation, and a major mobile security release — items that affect IoT, OT, ICS, CPS, industrial and critical‑infrastructure operations, and connected devices.

N-able Patches Critical Zero-Day in N-central

N-able issued the 2026.3 HF4 server-side hotfix for CVE-2026-86218, a CVSS 10 unauthenticated/pre-authentication remote code execution flaw in its N-central endpoint-management platform that the company says has been exploited in the wild. N-central hosted instances were patched by N-able; on‑premises administrators should apply HF4 immediately, review logs for connections from 23.234.64.0/18, and investigate unfamiliar newly created accounts, including accounts using .invalid email addresses.

Source: SecurityWeek

MikroTik Patches Critical Flaws Chained to Hack Routers

MikroTik released RouterOS fixes for six vulnerabilities after CERT Polska confirmed active exploitation of the MikroTrick chain, which combines CVE-2026-67276 (SSH authentication bypass) and CVE-2026-86060 (SSH privilege manipulation) to take full administrative control of devices with publicly accessible SSH. Administrators should immediately update to RouterOS 7.24.2, 7.23.4, or 6.49.21 (or 7.25beta3), restrict exposed management services to trusted networks, and investigate devices for unknown accounts, scripts, and configuration changes; the absence of MikroTik’s Flagged marker does not rule out earlier compromise.

Source: SecurityWeek

Forescout Warns AI Could Lower Barriers to PLC Exploit Development

Forescout’s Vedere Labs used AI assistance to port a pre‑authentication remote‑code‑execution exploit for CVE-2021-31886 from a WAGO 750-852 PLC to a WAGO 750-831 running firmware V01.04.16, enabling arbitrary ARM shellcode on the live controller without FTP credentials via exposed FTP port 21. The work required substantial researcher direction and an 8‑hour, 32‑minute final RCE session costing US$535.74 in API use; an attempted command‑and‑control extension permanently bricked the test PLC, and researchers warned that improving AI could reduce the cost and expertise needed to adapt embedded‑device exploits.

Source: Industrial Cyber

Report Warns Fragmented Federal Cyber Incident Reporting Diverts Response Resources

A McCrary Institute and U.S. Chamber of Commerce report, citing a July GAO review, identified 117 federal cybersecurity reporting regulations across 27 agencies, including 48 that apply to private industry, and says overlapping reporting can take time from containment and restoration during incidents. The report recommends a CISA‑led single intake process built on CIRCIA, with standardized reporting elements and use of CIRCIA’s substantially similar authority where legally permitted.

Source: Industrial Cyber

Samsung September 2026 Security Release Addresses 90 Issues

Samsung’s September 2026 Security Maintenance Release addresses 90 issues for eligible Galaxy devices: 58 Google patches, one Samsung Semiconductor patch, and 31 Samsung Mobile Vulnerabilities and Exposures (SVEs). Samsung’s bulletin identifies two critical SVE flaws in image decoders that can permit remote arbitrary‑code execution before SMR Sep‑2026 Release 1; organizations should deploy the update to eligible managed Galaxy devices as it becomes available.

Source: SamMobile

Actionable steps: apply N-central 2026.3 HF4 to on‑prem systems immediately and audit for suspicious accounts and connections from 23.234.64.0/18; update exposed MikroTik routers to the listed RouterOS versions and limit SSH/management access; prioritize OT vulnerability reachability and exploitability as Forescout recommends; review incident‑reporting procedures to avoid diverting response resources and align with CIRCIA guidance; and deploy the September 2026 Samsung SMR to eligible managed Galaxy devices when available.

Share this